Hudson Data

HD Trust · the session-trust layer

Session-trust intelligence for the AI-fraud era.

Classifies WHO is operating, WHAT device and runtime they are using, and HOW the session connects. Catching what fingerprinting platforms architecturally cannot see. For the bank, and for the customer being targeted.

3 axes · multi-channel session signal · structured actions · SOC 2 Type 2

Live decisioning · WHO × WHAT × HOW

sess_3f81b2

Four real session patterns. Three-axis classification. One verdict each.

Privacy-conscious customer · Brave + Tor

1 / 4
WHOscanning…
WHATscanning…
HOWscanning…

Matrix · WHO × WHAT × HOW → verdict

××

Verdict · action

3

classification axes

Multi-channel

session signals

Continuous

runtime evaluation

Real-time

decisioning latency

SOC 2 Type 2

certified

The three axes

WHO × WHAT × HOW in one decision.

Each axis compresses dozens of signals into a clear classification. Your team gets explicit, auditable outputs without exposing implementation details to attackers.

WHO

Operator identity + behavioral signal

Who is operating the session — and how are they acting?

LEGIT_OWNERCOACHEDSTOLEN_IDMULEBOT_SCRIPTAI_AGENT

Catches: Account takeover · stolen-identity application · mule operators · coached-fraud (scammer instructing the customer) · AI-agent operators · operator-change mid-session · scripted-input behavior · duress patterns · remote-access-tool-driven sessions

WHAT

Device, browser, runtime integrity

What is the device — and is it authentic?

AUTHENTICPRIVACYCOMPROMISEDHEADLESSSTEALTHAI_BROWSER

Catches: Stealth browsers (Multilogin / GoLogin / AdsPower) · banking trojans · remote-access trojans · headless and automated browsers · mobile emulators · runtime tampering · modified-OS devices · privacy browsers (Brave / Tor)

HOW

Connection integrity + transport

How is the session reaching you — and is it intact?

DIRECTPRIVACY_VPNPROXYTAMPERED

Catches: Commercial VPNs · residential proxy networks · mobile-proxy farms · datacenter IPs disguised as residential · Tor exit nodes · MITM redirection · session-replay attacks · SDK bypass tooling · transport-level tampering · geographic incoherence

Session-level threat coverage

Built for fraud that unfolds inside the session.

HD Trust tracks operator behavior, device integrity, and connection integrity together, preserving the context teams need when automation, coercion, malware, and proxy infrastructure overlap.

ThreatHow it presentsWhat incumbents seeWhat HD Trust sees
Voice-coercion of customerScammer on the phone walking your customer through a transaction.Allow — device is legitimate, session is authenticated.WHO catches coached-cadence + atypical destination + first-time rail + transaction-out-of-pattern.
Remote-access scam (RAT)Scammer running TeamViewer / AnyDesk on the customer's device.Allow — known device, owner is logged in.WHO + WHAT catch RAT signal, input-lag pattern, scripted UI interaction, mouse vs typing latency split.
AI-agent attackClaude/GPT/auto-browser controlling a real browser to apply for credit.Device looks real, browser fingerprint coherent.WHO catches inhuman timing, lack of micro-movement, decision-pause absence.
Stealth browserMultilogin / GoLogin / AdsPower with fresh, coherent fingerprint.New-device-but-coherent = allow.WHAT evaluates stealth-browser-specific integrity signals, while HOW evaluates SDK interaction and transport patterns.
Push-payment scam (romance / impersonation)Legitimate customer, legitimate device, fraudulent destination.No fraud signal — session is clean.WHO catches atypical-for-account behavior + stress / hesitation pattern. Combined with your payment-context (destination, beneficiary tenure), completes the detection.
Malware-mediated theftBanking trojan injecting form overlays or initiating background transactions.Form submission looks normal.HOW catches SDK tamper, transport tamper, payload replay; WHAT catches RAT/trojan presence.
MITM / proxy injectionAdversary intercepting and modifying responses or replays.TLS valid, allow.HOW catches transport tamper, replay signature, MITM-proxy indicators.

What HD Trust returns

No single score. A decision matrix you control.

Every decision is a structured object — not a black-box number. WHO, WHAT, and HOW classifications resolve into a cell of your matrix, and the cell is the action. Your downstream systems consume it directly; your investigators replay it; your auditors read every classification and signal that drove it.

FieldTypeDescription
who_classificationenumWho is operating the session — LEGIT_OWNER · COACHED · STOLEN_ID · MULE · BOT_SCRIPT · AI_AGENT. Resolved from identity continuity, network, telephony, and behavior signal.
what_classificationenumWhat device, browser, and runtime they are using — AUTHENTIC · PRIVACY · COMPROMISED · HEADLESS · STEALTH · AI_BROWSER. Resolved from environment integrity and resilience signal.
how_classificationenumHow the session reaches you — DIRECT · PRIVACY_VPN · PROXY · TAMPERED. Resolved from connection integrity, transport, and network signal.
actionenumAPPROVE · PROTECT · STEP_UP · REVIEW · BLOCK — read from the WHO × WHAT × HOW cell of your decisioning matrix. No single score; the matrix cell is the decision.
matrix_policy_versionstringWhich version of your decisioning matrix produced this verdict. Versioned and replayable.
dimension_evidenceobject<dimension, signal>Underlying evidence per axis — WHO, WHAT, HOW — plus network, telephony, behavior, and resilience signals. The inputs that drove the classifications.
reason_codesarray<code>Top-K explainable signal drivers, mapped to consumer-facing reason language where applicable.
linked_sessionsarray<session_id>Other recent sessions sharing identifiers or behavioral signature (consortium-aware).
trajectoryenumTrust trajectory across the session: STABLE · IMPROVING · DEGRADING · COMPROMISED.

How it plugs in

Eight ways into your stack.

Web, mobile, server, streaming, webhook, dashboard, data lake, SIEM. HD Trust meets your architecture — not the other way around.

Web SDK

JavaScript drop-in. Three lines of code. Collects behavioral, device, and network signal. SPA-aware.

Mobile SDKs

Native iOS (SPM / CocoaPods), Android (Gradle / Maven), React Native, Flutter, Capacitor. Background-safe, battery-conscious.

REST API

Server-side scoring. Authenticated calls return a full verdict object. Idempotent. Low-latency.

Streaming / gRPC

High-throughput pipelines (Kafka, Pub/Sub, gRPC). For real-time decisioning at issuer / acquirer / network volumes.

Webhooks

Live APPROVE / PROTECT / STEP_UP / BLOCK actions delivered to your downstream systems as the signal evolves through the session.

Dashboard

Investigate cases, tune thresholds, manage allow / negative lists, review verdict explainability, run replays.

Data-lake export

Stream every scored session into your data lake (S3, GCS, Snowflake, BigQuery, Databricks) for downstream analytics and audit retention.

SIEM integration

Splunk, Sentinel, Chronicle, Elastic. Trust events surface alongside the rest of your security telemetry.

Use cases

Wherever money or value — or trust — moves.

HD Trust scores the session at every point an attacker can move money, value, or identity — from the login screen to the final payout. And at every point a customer is being targeted by someone else who's trying to do the same.

Identity moments

Login & authentication

Credential stuffing, ATO, bot logins, session hijack, SIM-swap-driven access. Caught before they touch the application.

Account opening

Synthetic identity, application fraud, mule onboarding, KYC fraud — flagged at signup, not at the chargeback.

Account changes

Password, email, phone, device, beneficiary changes — the silent precursor to almost every ATO event.

Customer authentication

Voice-channel authentication, deepfake defense, high-stakes call verification with cross-channel coherence.

Money & value movement

Checkout & payments

Card-not-present, BNPL, wallet pay, P2P transfer — every transaction scored before authorization.

Withdrawals & payouts

ACH, wire, crypto, gift-card cash-out, lending disbursement — the moment funds leave the platform.

Push-payment review

Zelle, Real-Time Payments, RTP — scoring the legitimate-session-but-targeted-customer case.

Refunds & returns

Refund abuse, friendly fraud, returnless-refund exploit, return-of-empty-box schemes.

Promotion, marketplace & loyalty

Promo & loyalty redemption

Sign-up bonus farming, coupon stacking, loyalty-point cash-out, referral abuse.

Marketplace & e-commerce

Listing fraud, seller takeover, fake-review rings, on-platform value exchange.

KYC & document submission

Document forgery, deepfake selfies, recycled-identity packets — caught before the ops team reviews them.

Insurance applications

Bot-driven quoting, ghost-broker rings, agent-fraud signal at policy bind.

Deployment

Start with a focused SDK and server-side integration.

A focused integration.We don't replace your decisioning — we feed it a better signal that your existing rules consume.

1

Browser

Web or mobile collection

<script
  src="https://hudsondata.com/static/hd-detect.js"
  data-api-key="..."
  data-auto="true">
</script>

SDK observes the session in real time. No verdict ever reaches the browser.

2

Your backend

Server-side decision call

POST /v1/session/decide
  { session_id,
    binding_token,
    application_data }

Response:
  { action: APPROVE | PROTECT | STEP_UP
          | REVIEW  | BLOCK,
    who, what, how,
    reasons: [...] }

One call, one structured decision. Plug it into your existing rules engine.

Hudson-managed SaaS today. SOC 2 Type 2, US / EU / India data residency, per-tenant isolation.

Frequently asked

Questions buyers ask first.

The ones that come up in every first conversation. Honest answers, no marketing fog.

How is HD Trust different from device-fingerprinting platforms?

Fingerprinting platforms take a snapshot of the device and ask one question: is this device known and coherent. HD Trust monitors the whole session — and resolves it across three classifications: WHO is operating the session, WHAT device and runtime they are using, and HOW the session connects. A fingerprint is a point-in-time check. A session is a continuous behavior. That's a fundamentally different capability — not a feature upgrade.

Does HD Trust replace my existing fraud platform?

No. HD Trust feeds a better signal into the decisioning system you already run. Your rules engine consumes our verdict alongside your other signals. We're additive, not rip-and-replace.

How long does integration take?

The technical integration is a script tag or SDK plus a server-side decision call. A focused integration commonly takes 2–3 weeks once scope and security review are ready; calibration and a controlled production rollout follow the implementation plan agreed for your environment.

Does HD Trust output a fraud score?

No — that's the point. HD Trust returns a structured decision: WHO classification × WHAT classification × HOW classification → action (APPROVE / PROTECT / STEP_UP / REVIEW / BLOCK), with reasons. Your downstream system consumes structure, not a number.

What is PROTECT, and why is it a distinct action?

PROTECT exists for the case where the customer is legitimate but their device or environment is compromised. Instead of blocking your customer out of their own account, PROTECT warns them and steps up authentication. No fingerprinting platform has this verdict because they can't see WHO independently of WHAT.

Can we customize the decisioning matrix?

Yes. Every cell of the WHO × WHAT × HOW matrix is tunable per-org, per-action. A bank's STEP-UP for a stolen-ID on a privacy browser might be a marketplace's BLOCK. Same shape; your call.

What threats does HD Trust actually catch?

Stealth browsers, remote-access scams (TeamViewer, AnyDesk), AI-agent browser automation, customers being coached by scammers, malware-mediated theft, MITM attacks, push-payment scam behavioral patterns, account takeover, synthetic identity at account opening, mule onboarding — and the long tail of session-level threats that have evolved in the last 18 months.

Does HD Trust collect PII?

HD Trust collects device characteristics, behavioral patterns, network attributes, and identity-continuity signals. Depending on configuration and jurisdiction, behavioral signals may be regulated as personal, sensitive, or biometric information. Collection, notice, retention, and deletion controls are set through the customer agreement and deployment configuration.

Where does the data live?

Hudson-managed SaaS today, with US / EU / India data-residency options. Per-tenant isolation. SOC 2 Type 2. Customer-cloud (BYOC), hybrid, and on-prem are on the roadmap for enterprise engagements that require them.

How does HD Trust support GDPR and CCPA obligations?

Hudson Data documents the configured data flows, retention, deletion workflows, isolation controls, and contractual roles for each deployment. Compliance depends on the customer's use case, notices, lawful basis, configuration, and jurisdiction; it is reviewed during contracting rather than represented as a blanket product status.

How does HD Trust affect page-load performance?

Minimal. The SDK loads asynchronously; collection is non-blocking. Server-side decision latency is well inside standard authorization budgets — no perceptible delay to the user.

Does the verdict ever reach the browser?

No. The browser-side SDK observes and reports; verdicts only ever go to your backend. This is intentional — it prevents adversaries from reverse-engineering the decisioning logic or tampering with the response.

What happens if HD Trust is down?

Graceful degradation. Your decisioning system falls back to whatever default your rules engine specifies when the HD Trust signal is unavailable. We don't take your authorization path down with us.

Do you give us a dashboard and investigation tools?

Yes. An investigation interface for the cases your team needs to review, threshold-tuning controls, allow / negative list management, and replay of historical decisions.

How is HD Trust priced?

Per session scored, with volume tiers. Enterprise engagements include forward-deployed delivery (senior engineering and advisory). Pricing conversation happens after the AI-Fraud Audit so we both understand the scope.

Does HD Trust work across B2C, B2B, and marketplaces?

Yes. The three-axis model (WHO × WHAT × HOW) is industry-agnostic. The matrix defaults and threat coverage get tuned per industry pattern during the forward-deployed engagement.

How does HD Trust keep up with new threats?

The dimensional architecture is designed for evolution. New threats typically resolve into existing WHO / WHAT / HOW classifications without needing a new axis. When new classifications are needed, the matrix expands — and your existing integration keeps working.

Question not here? Send it our way →

What HD Trust isn't

Structured session intelligence, not another black-box score.

HD Trust is a three-axis decisioning matrix (WHO × WHAT × HOW) fed by explainable signal channels and composed at decision latency. It is designed for teams that need structured actions, replayable evidence, and policy control at the moment of risk.

Start with the audit

See where AI-era fraud is hitting you.

The AI-Fraud Audit produces a written assessment of your session-trust posture against the AI-era threats fingerprinting platforms miss. Vendor-neutral. Senior-team-delivered. Three weeks end-to-end.